Re: Real IP's

From: Todd Jones (jonest1_at_charter.net)
Date: 10/18/03


Date: Sat, 18 Oct 2003 04:58:37 -0500

I'm not sure if this is exactly what you are looking for, but it may be
what you want. Otherwise, you'll need to give further information, but
I'll give it a try.

First, I'm assuming you have servers (http, smtp) which serve incoming
connections from the internet. Therefore, I would place these servers
on a DMZ. How you configure your DMZ is up to you, but the two most
common methods is to do port forwarding onto some other network (not
internal and not internet), or to assign the actual IP addresses to the
boxes on the dmz and assign routes to each box. For this task, the most
common way to do this with hardware is with three network cards
(Internet, DMZ, LAN).

Iptables masquerades your lan traffic for you.

It sounds from your message below that your are considering port
forwarding to your lan. This is generally seen as a bad idea.

Todd Jones

Rex wrote:
> I'm re-doing our firewall at work and here's my situation.
>
> I'm running multiple servers with several different servers running
> duplicate services ie: http, smtp, etc.
>
> I'll be doing a iptables based firewall/router, my question is...
>
> 1. I can't use private ip's (192.168.0.x) and port forward, so how should I
> forward/masq my real ip's??
>
> 2. What tools work well ??
>
> Thanks
>
>



Relevant Pages

  • Re: Moving Exchange Server
    ... Placing them in the LAN gives internal users 100% access with no firewall to ... DMZ, thus 0% risk/ports open between them. ... If Microsoft Exchange and/or Active Directory cannot run ... >> Internet is better? ...
    (microsoft.public.exchange.setup)
  • Re: Domain in ISA2004 dmz
    ... put services that are needed to 'listen' for incoming internet requests ... DMZ trusts Seattle.Demo but seattle.demo does ... > Would it just be better if we left nothing but the web servers in the dmz ...
    (microsoft.public.isa)
  • Re: Where to place the DMZ zone?
    ... hypothetically lets say you have no DMZ hosting an email bridgehead ... If a hacker were to compromise one of your email or web servers (they are ... That is, the Internet accessible servers ... that can be compromised are on your internal network, ...
    (microsoft.public.isa)
  • Whats wrong with this topology?
    ... I've inherited a small corporate WinNT4.0 lan that I am reconfiguring to ... The funny thing about the setup is that the servers residing in the dmz are ... even though routing between interfaces on the dmz machines is disabled, ... region system (hostile internet vs. not very secure internal lan) because ...
    (Security-Basics)
  • Re: Correct routing/DNS config for dual-homed 2000 svr
    ... Your DMZ Servers should have one NIC that is connected to your firewall ... specified traffic in/out of of your DMZ and LAN. ... We have two internal DNS machines and are ...
    (microsoft.public.win2000.networking)